PT-2026-82111 · Veeam · Veeam One

CVE-2026-65641

·

Published

2026-08-26

·

Updated

2026-08-27

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Veeam ONE versions prior to 13.1.0.7233 Veeam ONE versions prior to 13.0.2.7159
Description An unauthenticated network attacker can coerce the Veeam ONE service account into performing SMB (Server Message Block) authentication. This action potentially exposes NTLM (New Technology LAN Manager) credentials, which are used for authentication in Windows environments.
Recommendations Update to version 13.1.0.7233. Update to version 13.0.2.7159.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65641

Affected Products

Veeam One